Skip to main content

5 mars 2025 Archivé

Generate and Use an External Signing Certificate for SAML Authentication in Omnissa Access

To use an external certificate for SAML signing, you must generate a Certificate Signing Request (CSR) from the Omnissa Access console. The CSR is sent to a certificate authority to generate the SAML signing certificate.

Note: To use an external signing certificate in the Omnissa Access service, you must generate the CSR that you send to the certificate authority from the Omnissa Access console.

Generate the Certificate Signing Request

Procedure

  1. In the Omnissa Access console Resources > Web Apps page, select Settings > SAML Metadata.

  2. Open the Generate CSR tab.

  3. Enter the requested information.

    OptionDescription
    Common NameEnter the fully qualified domain name. For example, www.example.com
    OrganizationEnter the legally registered name of the organization. For example, Mycompany, Inc.
    DepartmentEnter the department in your company that is added in the certificate. For example, IT Services.
    CityEnter the city where your organization is legally located.
    State/ProvinceEnter the state or region where your organization is located. Do not abbreviate.
    CountryEnter a few letters of your country name to select the correct country from the list.
    Key Generation AlgorithmSelect the secure hash algorithm used to sign the CSR.
    Key SizeSelect the number of bits used in the key. RSA 2048 is recommended. RSA key size smaller than 2048 is considered insecure.
  4. Click Generate.

Copy the CSR and give it to the certificate authority who will create the certificate.

Upload a Certificate Authority Signing Certificate

When you receive the certificate, upload the certificate to the Omnissa Access service. The CA replaces the self-signed certificate.

  1. In the Omnissa Access console Resources > Web Apps page, select Settings > SAML Metadata

  2. Open the Generate CSR tab.

  3. Click Upload Certificate and navigate to the certificate.

  4. Click Open.

    The SAML signing certificate and the SAML metadata files in Omnissa Access console are updated with the new certificate.

  5. Go to the Integrations > Connectors page and click Restart for each connector.

    The metadata is updated in the connector.

Next, reconfigure all SAML service provider and identity provider configurations with the updated SAML metadata file. If this is not done, SAML transactions fail and single sign-on does not work. See Download the SAML Signing Certificate from Omnissa Access to Configure with Relying Applications.

Cette page vous a-t-elle été utile ?

Envoyer un commentaire sur cette rubrique

Cette rubrique vous a-t-elle été utile ?

N'indiquez aucune information personnelle ou confidentielle.

Génération du lien…